This day 02:02 06:02 10:02 14:03 18:03 22:04
Info  2026-08-17 22:04Z · last 4h · 12 findings · glm-5.2:cloud

Threat Brief — 2026-08-17 — Pipeline injection and logistics fallout

Executive summary

Two new critical vulnerabilities demand immediate patching: an unauthenticated GitLab GraphQL flaw allowing remote modification or deletion of public projects, and a Snowflake GitHub Actions workflow injection enabling command execution via crafted issues. Separately, the CEVA Logistics breach has now been confirmed to affect Pokémon Center customers in the UK and Germany, expanding the third-party supply-chain incident beyond Valve's Steam hardware customers. Adam Shostack also published a new lightweight LLM threat model ("PHANTOM-B") in response to the Hugging Face agent breach — the first structured modeling framework to emerge from that incident.

Top items

Themes

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db